VYPR

Joplin

by Joplin

npm: joplin

Source repositories

CVEs (33)

  • CVE-2026-34600MedMay 19, 2026
    risk 0.30cvss 5.7epss 0.00

    Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Versions 3.5.2 and prior contain a logic error in the delta API that allows share recipients to download notes that are no longer shared with them, related to but not fully…

  • CVE-2025-57798MedMay 19, 2026
    risk 0.29cvss 5.5epss 0.00

    Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Versions 3.6.14 and prior contain a Denial of Service (DoS) vulnerability in the title input functionality due to a lack of proper length validation. This flaw allows an…

  • CVE-2021-23431MedAug 24, 2021
    risk 0.28cvss 5.4epss 0.00

    The package joplin before 2.3.2 are vulnerable to Cross-site Request Forgery (CSRF) due to missing CSRF checks in various forms.

  • CVE-2026-46650MedSep 21, 2026
    risk 0.22cvss 4.4epss 0.00

    Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.2, isAcceptedUrl() in packages/renderer/htmlUtils.ts uses an unanchored regular expression for internal resource URLs, allowing a javascript: URL containing a…

  • CVE-2026-59815MedSep 21, 2026
    risk 0.21cvss 4.3epss 0.00

    Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.7, Joplin Server's ItemModel.checkIfAllowed() authorizes writes to items with a share ID when any share_users row exists for the caller, without requiring…

  • CVE-2026-59816MedSep 21, 2026
    risk 0.21cvss 4.3epss 0.00

    Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.7, the GET /api/transcribe/:id and POST /api/transcribe/:id handlers in packages/server/src/routes/api/transcribe.ts on Joplin Server instances with…

  • CVE-2026-49449LowSep 21, 2026
    risk 0.09cvss 2.5epss 0.00

    Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. From 1.4.0 until 3.7.2, packages/renderer/MdToHtml/rules/katex.ts enables KaTeX's trust option for note content, allowing a note author to place a \href URL into rendered…

  • CVE-2025-27409HigApr 30, 2025
    risk 0.00cvss 7.5epss 0.01

    Joplin is a free, open source note taking and to-do application, which can handle a large number of notes organised into notebooks. Prior to version 3.3.3, path traversal is possible in Joplin Server if static file path starts with `css/pluginAssets` or `js/pluginAssets`. The…

  • CVE-2025-27134HigApr 30, 2025
    risk 0.00cvss 8.8epss 0.02

    Joplin is a free, open source note taking and to-do application, which can handle a large number of notes organised into notebooks. Prior to version 3.3.3, a privilege escalation vulnerability exists in the Joplin server, allowing non-admin users to exploit the API endpoint…

  • CVE-2025-25187HigFeb 7, 2025
    risk 0.00cvss 7.8epss 0.00

    Joplin is a free, open source note taking and to-do application, which can handle a large number of notes organised into notebooks. This vulnerability is caused by adding note titles to the document using React's `dangerouslySetInnerHTML`, without first escaping HTML entities.…

  • CVE-2025-24028HigFeb 7, 2025
    risk 0.00cvss 7.8epss 0.01

    Joplin is a free, open source note taking and to-do application, which can handle a large number of notes organised into notebooks. This vulnerability is caused by differences between how Joplin's HTML sanitizer handles comments and how the browser handles comments. This affects…

  • CVE-2024-55630LowFeb 7, 2025
    risk 0.00cvss 3.3epss 0.00

    Joplin is a free, open source note taking and to-do application, which can handle a large number of notes organised into notebooks. Joplin's HTML sanitizer allows the `name` attribute to be specified. If `name` is set to the same value as an existing `document` property (e.g.…

  • CVE-2023-39517HigJun 21, 2024
    risk 0.00cvss 8.2epss 0.00

    Joplin is a free, open source note taking and to-do application. A Cross site scripting (XSS) vulnerability in affected versions allows clicking on an untrusted image link to execute arbitrary shell commands. The HTML sanitizer (`packages/renderer/htmlUtils.ts::sanitizeHtml`)…

Page 2 of 2